ChainGate Ops

Collect the changes.
Keep the context.

Ops is ChainGate’s private collection and analysis system. It retains package observations, compares releases, and produces findings and historical seed artifacts.

Current access

Ops is maintained infrastructure, not a public hosted service. There is no public Ops installer, API, or corpus download. Developers can use the public Runtime CLI.

See the implemented components
From registry observations to retained evidence
Registry sources

npm metadata and change feed
PyPI metadata · OSV advisories

Historical store

Versions, artifact declarations, publication and observation times, change records

Analysis

Findings, contextual records, email digests

Seed generation

Snapshot → derived history → SQLite artifact

Runtime boundary

Runtime reads a locally supplied seed file. See the distribution status.

What the system does

Implemented collection and analysis, with separate outputs for inspection and Runtime.

Observe registry changes

An npm change-feed watcher refreshes packages in the selected corpus. Periodic reconciliation provides a second collection path. Separate collectors retrieve PyPI metadata and OSV advisories.

The collected scope is selected packages, not every package in either registry. PyPI collection does not imply PyPI Runtime enforcement.

Retain release history

The historical store retains versions, publisher and maintainer metadata, provenance indicators, dependencies, install-script declarations, artifact hashes and sizes, and publication and observation times.

Change and mismatch records preserve comparisons with earlier observations. Disappearances and reappearances are recorded as events; incoming metadata does not simply replace every historical field.

Compare related changes

Analysis includes publisher and maintainer transitions, combined publisher/provenance/install/size/git changes within release lines, and coordinated publishing across packages.

Other components identify same-version artifact metadata changes, package takedowns, reappearances, and unusual movements of the latest tag. These produce findings for inspection; they do not directly block a developer’s install.

Produce inspectable outputs

Stored findings include the package/version, contributing changes, timing, and supporting context. Alert components select findings for email digests and track delivery progress.

Collection monitoring records progress, failures, and coverage gaps. Those health records describe the collection system; they are distinct from findings about a package.

How evidence reaches Runtime

Seed-generation code extracts a consistent historical snapshot and builds a SQLite artifact with release lineages, change records, and exact-version advisory pins. Runtime opens a supplied artifact locally to evaluate a candidate.

The legacy witness-seed exporter and the v3 detection-seed builder are separate implementations. Installing a legacy witness seed does not enable v3 detection.

The artifact path exists. Public v3 delivery does not.

The v3 producer and Runtime reader are implemented, but no v3 seed is publicly distributed. The current seed candidate is unsigned. There is no live feed from Ops findings or alerts into a user’s Runtime installation.

Runtime availability and setup

Capability summary checked against the collection, reconciliation, analysis, alerting, and seed-generation implementations on October 4, 2026. Operational records and infrastructure are private. The public Runtime code’s Apache-2.0 license does not grant access to the Ops system or its corpus.